Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
9/29/2010 7:46:42 AM
mbam-log-2010-09-29 (07-46-42).txt
Scan type: Quick scan
Objects scanned: 124522
Time elapsed: 9 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 9/29/2010 7:53:19 AM - Run 3
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\FMS\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 461.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.18 Gb Total Space | 50.54 Gb Free Space | 71.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 5.45 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 1.91 Gb Total Space | 1.77 Gb Free Space | 93.07% Space Free | Partition Type: FAT
Drive G: | 7.52 Gb Total Space | 7.48 Gb Free Space | 99.54% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: STN1
Current User Name: FMS
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\FMS\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iolo\System Shield\ioloSSTray.exe ()
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe (Authentium, Inc)
PRC - C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe (Authentium, Inc)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Active-Charge\Active-Charge.Exe (VeriFone, Inc.)
PRC - C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe (Qwest)
PRC - C:\Advanced Wheel Mouse\wh_exec.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\EloDkMon.exe (Elo Touchsystems, Inc.)
PRC - C:\WINDOWS\system32\EloSrvce.exe (Elo Touchsystems, Inc.)
PRC - C:\WINDOWS\system32\EloTTray.exe (Elo Touchsystems, Inc.)
PRC - C:\Program Files\Verizon Wireless\VZAccess Manager\Drivers\Palm\PalmOneLiveConnect.exe (Palm, Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Verizon Wireless\VZAccess Manager\Drivers\Palm\TetherApp.exe (June Fabrics Technology, Inc.)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\MSSQL7\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\MSSQL7\Binn\sqlmangr.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\FMS\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\WMVCore.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\winsta.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\sti.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\shgina.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\odbc32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netui1.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netui0.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ntlanman.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netrap.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msgina.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\drprov.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\davclnt.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\odbcint.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wmasf.dll (Microsoft Corporation)
MOD - C:\Program Files\Qwest\QuickCare\bin\sprthook.dll (SupportSoft, Inc.)
MOD - C:\Advanced Wheel Mouse\wh_hook.dll ()
========== Win32 Services (SafeList) ==========
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe File not found
SRV - (ioloSystemService) -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
SRV - (ioloFileInfoList) -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe ()
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (vseqrts) -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe (Authentium, Inc)
SRV - (vsedsps) -- C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe (Authentium, Inc)
SRV - (vseamps) -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe (Authentium, Inc)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AdobeActiveFileMonitor8.0) -- C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (EloSystemService) -- C:\WINDOWS\system32\EloSrvce.exe (Elo Touchsystems, Inc.)
SRV - (MSSQLServer) -- C:\MSSQL7\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLServerAgent) -- C:\MSSQL7\Binn\sqlagent.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (AMP) -- C:\WINDOWS\system32\drivers\amp.sys (Authentium, Inc)
DRV - (AMPSE) -- C:\WINDOWS\system32\drivers\ampse.sys (Authentium, Inc)
DRV - (mf) -- C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (PalmUSBD) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (whfltr2k) -- C:\WINDOWS\system32\drivers\whfltr2k.sys ()
DRV - (ASCTRM) -- C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (EloUsb) -- C:\WINDOWS\system32\drivers\EloUsb.Sys (Elo Touchsystems, Inc.)
DRV - (elomoufiltr) -- C:\WINDOWS\system32\drivers\elofiltr.sys (Elo Touchsystems, Inc.)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (palmmdm) -- C:\WINDOWS\system32\drivers\palmmdm.sys (June Fabrics Technology Inc.)
DRV - (DSproct) -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (DRVMCDB) -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SMNDIS5) -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (MagEpNt) -- C:\WINDOWS\System32\drivers\magepnt.sys (MagTek)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0061019
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co...html?channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0061019
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0061019
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co...html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.co.../www.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.chase.com/Chase.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\Firefox [2010/05/24 12:56:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/07/10 03:07:50 | 000,000,000 | ---D | M]
[2010/09/16 09:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\Mozilla\Extensions
[2010/09/16 09:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\Mozilla\Firefox\Profiles\59fke6ln.default\extensions
[2010/09/16 09:27:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Bing Bar] C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [PalmTether] C:\Program Files\Verizon Wireless\VZAccess Manager\Drivers\Palm\TetherApp.exe (June Fabrics Technology, Inc.)
O4 - HKLM..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe (Qwest)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WheelMouse] C:\Advanced Wheel Mouse\wh_exec.exe ()
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\MSSQL7\Binn\sqlmangr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O4 - Startup: C:\Documents and Settings\FMS\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\FMS\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} https://ra.qwest.com...ad/tgctlins.cab (SupportSoft Installer)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1184337109265 (WUWebControl Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com...obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\FMS\Local Settings\Temporary Internet Files\Content.IE5\EO3YVIRI\Country Cleaners Logo.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\FMS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/12/11 14:03:59 | 000,000,277 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 90 Days ==========
[2010/09/29 07:30:33 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\TFC.exe
[2010/09/28 13:26:24 | 001,293,400 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\FMS\Desktop\TDSSKiller.exe
[2010/09/28 11:33:27 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/09/22 06:24:25 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\OTL.exe
[2010/09/22 06:17:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\unknown
[2010/09/22 06:14:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Local Settings\Application Data\WinZip
[2010/09/21 06:21:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Application Data\Malwarebytes
[2010/09/21 06:19:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/21 06:19:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/21 06:19:46 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/20 07:00:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/09/20 06:59:29 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/09/20 06:58:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/20 06:50:49 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\OTL.exe
[2010/09/20 06:49:34 | 006,153,384 | ---- | C] (Malwarebytes Corporation ) -- C:\lacey.exe
[2010/09/20 06:48:33 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\erunt-setup.exe
[2010/09/20 06:47:26 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\TFC.exe
[2010/09/18 07:43:38 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/09/18 06:43:28 | 001,913,056 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\FMS\Desktop\HousecallLauncher.exe
[2010/09/17 13:00:30 | 000,000,000 | ---D | C] -- C:\iolo
[2010/09/17 12:20:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\iolo
[2010/09/17 12:15:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Authentium
[2010/09/17 12:14:46 | 000,118,784 | ---- | C] (iolo technologies, LLC) -- C:\WINDOWS\System32\iavlsp.dll
[2010/09/17 12:14:40 | 000,000,000 | ---D | C] -- C:\Program Files\iolo
[2010/09/17 12:08:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Application Data\iolo
[2010/09/17 12:08:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\iolo
[2010/09/17 06:52:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/09/17 06:34:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2010/09/17 06:34:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010/09/17 06:34:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2010/09/17 06:34:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010/09/17 06:27:47 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010/09/16 16:56:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/09/16 16:51:42 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010/09/16 16:32:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ScanSoft(2)
[2010/09/16 16:27:37 | 000,000,000 | ---D | C] -- C:\Program Files\FinalMediaPlayer
[2010/09/16 14:29:29 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\FMS\IECompatCache
[2010/09/16 10:17:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\FMS\PrivacIE
[2010/09/16 10:16:18 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\FMS\IETldCache
[2010/09/16 10:11:36 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/09/16 09:28:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Local Settings\Application Data\Mozilla
[2010/09/16 09:28:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Application Data\Mozilla
[2010/09/16 09:27:40 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/09/15 07:20:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\FMS\Application Data\Brother
[2010/09/15 07:15:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Local Settings\Application Data\Scansoft
[2010/09/15 07:10:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\My Documents\My PaperPort Documents
[2010/09/15 06:55:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\BrFaxRx
[2010/09/15 06:54:24 | 000,054,784 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\brinsstr.dll
[2010/09/15 06:54:11 | 000,063,488 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\BrNetSti.dll
[2010/09/15 06:54:11 | 000,058,368 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\BrWiaNCp.dll
[2010/09/15 06:54:11 | 000,041,472 | ---- | C] (Brother Industries,Ltd) -- C:\WINDOWS\System32\Brnsplg.dll
[2010/09/15 06:54:09 | 001,397,248 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\BrWia07b.dll
[2010/09/15 06:54:09 | 000,094,208 | ---- | C] (Brother Industries Ltd) -- C:\WINDOWS\System32\BRRBTOOL.EXE
[2010/09/15 06:54:09 | 000,077,824 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\BRLMW03A.DLL
[2010/09/15 06:54:09 | 000,024,223 | ---- | C] (brother Industries Ltd) -- C:\WINDOWS\System32\BRLM03A.DLL
[2010/09/15 06:54:08 | 000,000,000 | ---D | C] -- C:\Brother
[2010/09/15 06:54:06 | 000,167,936 | ---- | C] (brother) -- C:\WINDOWS\System32\NSSearch.dll
[2010/09/15 06:54:05 | 000,131,072 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\brunin03.dll
[2010/09/15 06:54:05 | 000,102,400 | ---- | C] (Brother Industries,LTD.) -- C:\WINDOWS\System32\BrMfNt.dll
[2010/09/15 06:54:05 | 000,073,728 | ---- | C] (Brother Industories Ltd. P&S Company) -- C:\WINDOWS\System32\BRCrypt.dll
[2010/09/15 06:54:05 | 000,000,000 | ---D | C] -- C:\Program Files\Brother
[2010/09/15 06:49:54 | 000,000,000 | ---D | C] -- C:\Program Files\Nuance
[2010/09/15 06:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\ScanSoft
[2010/09/15 06:47:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Brother
[2010/07/10 03:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/07/09 12:52:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\FMS\Application Data\FinalMediaPlayer
[2010/07/02 06:18:06 | 000,000,000 | ---D | C] -- C:\Advanced Wheel Mouse
========== Files - Modified Within 90 Days ==========
[2010/09/29 07:36:19 | 000,000,448 | ---- | M] () -- C:\WINDOWS\System32\iolo.ini
[2010/09/29 07:35:21 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/29 07:34:55 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/29 07:34:51 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/09/29 07:34:25 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/29 07:34:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/29 07:34:21 | 1063,407,616 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/29 07:33:45 | 003,772,416 | ---- | M] () -- C:\Documents and Settings\FMS\ntuser.dat
[2010/09/29 07:33:23 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\FMS\ntuser.ini
[2010/09/29 07:29:36 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\TFC.exe
[2010/09/29 07:03:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/29 06:48:52 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\dds.scr
[2010/09/29 06:14:10 | 000,031,568 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\rootkitunhookerreport
[2010/09/29 06:11:36 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\MBRCheck.exe
[2010/09/28 12:09:16 | 000,001,947 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/28 11:52:25 | 000,032,072 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\rootkitunhookerlog
[2010/09/28 11:31:08 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\RKUnhookerLE.EXE
[2010/09/27 06:02:45 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\Notepad.lnk
[2010/09/22 06:39:15 | 000,002,443 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\HiJackThis.lnk
[2010/09/22 06:22:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\OTL.exe
[2010/09/21 15:43:32 | 001,193,882 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\tdsskiller.zip
[2010/09/21 06:19:52 | 000,000,728 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\LAcey.lnk
[2010/09/20 07:00:08 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\TFC.exe
[2010/09/20 06:59:42 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\FMS\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/09/20 06:59:37 | 000,000,643 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\NTREGOPT.lnk
[2010/09/20 06:59:37 | 000,000,624 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\ERUNT.lnk
[2010/09/20 06:59:16 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\erunt-setup.exe
[2010/09/20 06:58:31 | 006,153,384 | ---- | M] (Malwarebytes Corporation ) -- C:\lacey.exe
[2010/09/20 06:58:23 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
[2010/09/18 07:04:26 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\FMS\Start Menu\Programs\Startup\Palm Registration.lnk
[2010/09/18 06:45:00 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\FMS\Local Settings\Application Data\housecall.guid.cache
[2010/09/18 06:43:44 | 001,913,056 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\FMS\Desktop\HousecallLauncher.exe
[2010/09/18 06:13:01 | 000,001,721 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\System Shield.lnk
[2010/09/18 03:20:16 | 000,251,880 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/18 03:04:13 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/09/17 12:54:58 | 000,459,696 | ---- | M] () -- C:\ss_dm.exe
[2010/09/17 12:09:27 | 000,074,703 | ---- | M] () -- C:\WINDOWS\System32\mfc45.dll
[2010/09/17 10:03:04 | 000,066,216 | ---- | M] () -- C:\Documents and Settings\FMS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/17 06:54:41 | 000,441,626 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/17 06:54:41 | 000,381,692 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/09/17 06:54:41 | 000,053,436 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/09/17 06:53:31 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010/09/17 06:49:09 | 002,105,070 | ---- | M] () -- C:\WINDOWS\iis6.BAK
[2010/09/17 06:30:54 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/16 14:14:29 | 000,000,009 | ---- | M] () -- C:\WINDOWS\Brfaxrx.ini
[2010/09/16 10:16:21 | 000,000,847 | ---- | M] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/16 09:27:43 | 000,001,652 | ---- | M] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/16 09:27:43 | 000,001,634 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/09/15 10:43:43 | 000,006,906 | ---- | M] () -- C:\Documents and Settings\FMS\Application Data\wklnhst.dat
[2010/09/15 06:55:25 | 000,000,410 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2010/09/15 06:55:02 | 000,000,225 | ---- | M] () -- C:\WINDOWS\Brpfx04a.ini
[2010/09/15 06:55:02 | 000,000,093 | ---- | M] () -- C:\WINDOWS\brpcfx.ini
[2010/09/07 14:44:52 | 001,293,400 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\FMS\Desktop\TDSSKiller.exe
[2010/08/27 07:35:47 | 000,919,384 | ---- | M] () -- C:\Documents and Settings\FMS\My Documents\CountryCleanersMMDSept10.pdf
[2010/07/30 07:20:36 | 000,912,333 | ---- | M] () -- C:\Documents and Settings\FMS\My Documents\CountryCleanersMMDAug10 1.pdf
[2010/07/14 06:26:24 | 000,000,482 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/07/09 12:52:17 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\FinalMediaPlayer.lnk
[2010/07/09 12:52:17 | 000,000,810 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\FinalMediaPlayer.lnk
========== Files Created - No Company Name ==========
[2010/09/29 06:50:00 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\dds.scr
[2010/09/29 06:14:43 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\MBRCheck.exe
[2010/09/29 06:14:10 | 000,031,568 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\rootkitunhookerreport
[2010/09/28 13:30:35 | 000,000,448 | ---- | C] () -- C:\WINDOWS\System32\iolo.ini
[2010/09/28 13:26:06 | 001,193,882 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\tdsskiller.zip
[2010/09/28 12:09:16 | 000,001,947 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/28 11:52:21 | 000,032,072 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\rootkitunhookerlog
[2010/09/28 11:47:55 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\RKUnhookerLE.EXE
[2010/09/25 05:58:11 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\gmer.exe
[2010/09/21 06:19:52 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\LAcey.lnk
[2010/09/20 06:59:42 | 000,000,799 | ---- | C] () -- C:\Documents and Settings\FMS\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/09/20 06:59:37 | 000,000,643 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\NTREGOPT.lnk
[2010/09/20 06:59:37 | 000,000,624 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\ERUNT.lnk
[2010/09/18 07:43:39 | 000,002,443 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\HiJackThis.lnk
[2010/09/18 06:45:00 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\FMS\Local Settings\Application Data\housecall.guid.cache
[2010/09/17 12:54:37 | 000,459,696 | ---- | C] () -- C:\ss_dm.exe
[2010/09/17 12:14:56 | 000,001,721 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\System Shield.lnk
[2010/09/17 12:09:27 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2010/09/16 09:27:43 | 000,001,652 | ---- | C] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/16 09:27:43 | 000,001,634 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/09/15 06:55:25 | 000,000,410 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/09/15 06:55:02 | 000,000,225 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2010/09/15 06:55:02 | 000,000,093 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2010/09/15 06:54:53 | 003,772,416 | ---- | C] () -- C:\Documents and Settings\FMS\ntuser.dat
[2010/09/15 06:54:09 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BRTCPCON.DLL
[2010/09/15 06:54:09 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2010/09/15 06:54:07 | 000,000,009 | ---- | C] () -- C:\WINDOWS\Brfaxrx.ini
[2010/09/15 06:54:05 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2010/08/27 07:35:47 | 000,919,384 | ---- | C] () -- C:\Documents and Settings\FMS\My Documents\CountryCleanersMMDSept10.pdf
[2010/07/30 07:20:36 | 000,912,333 | ---- | C] () -- C:\Documents and Settings\FMS\My Documents\CountryCleanersMMDAug10 1.pdf
[2010/07/14 06:46:12 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\Outlook Express.lnk
[2010/07/09 12:52:17 | 000,000,828 | ---- | C] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\FinalMediaPlayer.lnk
[2010/07/09 12:52:17 | 000,000,810 | ---- | C] () -- C:\Documents and Settings\FMS\Desktop\FinalMediaPlayer.lnk
[2009/07/27 06:28:10 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\FMS\Application Data\dvd.bmk
[2007/07/16 10:21:41 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\TECK.dll
[2007/07/16 10:21:39 | 000,843,776 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2007/07/16 10:21:39 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2007/07/12 13:02:43 | 000,438,272 | ---- | C] () -- C:\WINDOWS\System32\tls704d.dll
[2007/07/12 13:02:43 | 000,409,600 | ---- | C] () -- C:\WINDOWS\System32\NOVA_API.dll
[2007/07/12 13:02:43 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\cmeparse.dll
[2007/07/12 13:02:43 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\ipinplus32.dll
[2007/07/12 12:51:57 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2007/03/29 11:04:52 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\FMS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/26 19:29:41 | 000,006,906 | ---- | C] () -- C:\Documents and Settings\FMS\Application Data\wklnhst.dat
[2007/01/25 09:45:02 | 000,006,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\whfltr2k.sys
[2006/12/16 08:43:53 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\FMS\Local Settings\Application Data\fusioncache.dat
[2006/12/05 14:05:40 | 000,002,516 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/12/05 14:05:40 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\A777487C0E.sys
[2006/11/29 11:27:21 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/10/18 23:19:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/18 23:15:08 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/18 23:11:02 | 000,000,126 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/10/18 22:42:52 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/11 16:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 16:11:31 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[1999/06/05 15:47:06 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\MSPOS_USB.dll
========== LOP Check ==========
[2007/02/15 14:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2010/09/17 12:21:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2010/09/16 16:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft(2)
[2007/12/06 01:32:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2006/10/18 23:05:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/20 09:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/10 12:52:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\FinalMediaPlayer
[2007/02/15 14:42:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\HotSync
[2010/09/18 07:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\iolo
[2007/02/15 14:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\Leadertech
[2007/02/15 14:47:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\Smith Micro
[2007/02/26 19:29:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\FMS\Application Data\Template
[2006/11/29 11:20:38 | 000,000,258 | ---- | M] () -- C:\WINDOWS\Tasks\ISP signup reminder 1.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/02/12 14:56:23 | 000,001,654 | ---- | M] () -- C:\additdiag.txt
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2006/11/29 11:20:39 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2004/08/11 16:15:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2006/10/18 22:47:08 | 000,005,856 | RH-- | M] () -- C:\dell.sdr
[2010/09/20 06:59:16 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\erunt-setup.exe
[2010/09/29 07:34:21 | 1063,407,616 | -HS- | M] () -- C:\hiberfil.sys
[2006/11/29 11:44:15 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2006/10/18 23:05:55 | 000,000,828 | -H-- | M] () -- C:\IPH.PH
[2010/02/18 08:40:44 | 000,919,840 | ---- | M] (Sun Microsystems, Inc.) -- C:\JavaSetup6u18-rv.exe
[2010/09/20 06:58:31 | 006,153,384 | ---- | M] (Malwarebytes Corporation ) -- C:\lacey.exe
[2004/08/11 16:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/09/17 06:30:54 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/20 06:58:23 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
[2010/09/29 07:34:20 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[2010/09/17 12:54:58 | 000,459,696 | ---- | M] () -- C:\ss_dm.exe
[2006/10/18 23:06:01 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
[2010/09/28 13:28:58 | 000,048,672 | ---- | M] () -- C:\TDSSKiller.2.4.2.1_28.09.2010_13.26.30_log.txt
[2010/09/20 07:00:08 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\TFC.exe
[2009/10/20 09:18:53 | 014,308,680 | ---- | M] () -- C:\winzip140.exe
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/11 16:14:22 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/11 16:06:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/11 16:06:14 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/11 16:06:14 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/17 06:35:17 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/11/29 11:22:24 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/11 16:20:42 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\FMS\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/12/15 11:24:48 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\gmer.exe
[2010/09/18 06:43:44 | 001,913,056 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\FMS\Desktop\HousecallLauncher.exe
[2010/09/29 06:11:36 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\MBRCheck.exe
[2010/09/22 06:22:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\OTL.exe
[2010/09/28 11:31:08 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\FMS\Desktop\RKUnhookerLE.EXE
[2010/09/07 14:44:52 | 001,293,400 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\FMS\Desktop\TDSSKiller.exe
[2010/09/29 07:29:36 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\FMS\Desktop\TFC.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/04 04:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/11/29 11:22:23 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\FMS\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/09/15 06:23:24 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\FMS\Cookies\desktop.ini
[2010/09/29 07:35:58 | 000,131,072 | ---- | M] () -- C:\Documents and Settings\FMS\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2004/09/15 11:27:54 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.exe >
[2008/04/13 18:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< %USERPROFILE%\Templates\*.tmp >
< %SYSTEMDRIVE%\explorexxx.exe\*.* >
< %Windir%\Installer\*.tmp >
< %systemroot%\System32\*.xco >
< %ProgramFiles%\system32\*.* >
< %systemroot%\System32\windos\*.* >
< %SystemRoot%\system32\sandbox\*.* >
< %SystemRoot%\system32\*.amo >
< %SystemRoot%\system32\Windows Live\*.* >
< %ProgramFiles%\logs\*.* >
< %ProgramFiles%\Bifrost\*.* >
< %SystemRoot%\system32\*.goo >
< %systemroot%\system32\IME\*.* >
< %systemroot%\BackUp\*.* >
< %systemroot%\system32\*.ico >
< %systemroot%\system\*.dat >
< %systemroot%\system\*.exe >
< %AppData%\Macromedia\Common\*.* >
< %SYSTEMDRIVE%\dir\*.* /s >
< %systemroot%\system32\ras\*.exe >
< %SYSTEMDRIVE%\MFILES\*.* >
< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >
< %systemroot%\system32\services\*.* >
< %systemroot%\Spooler\*.* >
< %ProgramFiles%\system32\*.* >
< %systemroot%\system32\Setup\*.dll /x >
< %systemroot%\system32\*.mine >
< %SYSTEMDRIVE%\cleansweep.exe\*.* >
< %systemroot%\system32\ras\*.dll >
< %systemroot%\system32\ras\*.drv >
< %systemroot%\*.iq >
< %systemroot%\system32\XP\*.* >
< %SYSTEMDRIVE%\Extracted\*.* >
< %systemroot%\system32\windows\*.* >
< %systemroot%\logs\*.* >
< %SYSTEMDRIVE%\Win.Msi\*.* >
< %systemroot%\regedit\*.* >
< %systemroot%\system32\skype\*.* >
< %AppData%\Adobe\dlluplwin25\*.* >
< %UserProfile%\*.dat >
[2010/09/29 07:33:45 | 003,772,416 | ---- | M] () -- C:\Documents and Settings\FMS\ntuser.dat
< %UserProfile%\*.dll >
< %systemroot%\system32\*.sxo >
< %SYSTEMDRIVE%\Gazma\*.* /s >
< %systemroot%\system32\spynet\*.* >
< %systemroot%\system32\System\*.* >
< %appdata%\Microsoft\Windows\*.* >
< %systemroot%\system32\WinDir\*.* >
< %systemroot%\_\*.* >
< %systemroot%\system32\windows32\*.* >
< %ProgramFiles%\win\*.* >
< %AppData%\Microsoft\CD Burning\*.* >
< %systemroot%\*.cab >
< %systemroot%\K.Backup\*.* >
< %ProgramFiles%\Massenger\*.* >
< %systemroot%\System32\*.doc >
< %systemroot%\Office12\*.* >
< %systemroot%\System32\Rundl32.exe\*.* >
< %ProgramFiles%\yahoo.net\*.* >
< %systemroot%\system32\*.igo >
< %systemroot%\*.rew >
< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2003/08/06 02:32:32 | 000,151,552 | ---- | M] (SHARP Corporation) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\SC1BSTMN.EXE
< %USERPROFILE%\.COMMgr\*.* >
< %USERPROFILE%\Desktop\*.bat >
< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
[2006/10/18 23:05:40 | 000,043,008 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv
[2006/10/18 23:05:40 | 000,080,384 | ---- | M] () -- C:\Program Files\Common Files\Real\Visualizations\CosmicBelt.rpv
[2006/10/18 23:05:40 | 000,007,168 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Visualizations\Fire.rpv
[2006/10/18 23:05:40 | 000,007,680 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv
[2006/10/18 23:05:40 | 000,069,632 | ---- | M] () -- C:\Program Files\Common Files\Real\Visualizations\Nebula.rpv
< %PROGRAMFILES%\Internet Explorer\*.Jmp >
< %PROGRAMFILES%\Windows NT\system\*.dll >
< %systemroot%\system32\*.ext >
< %systemroot%\system32\Com\*.cfg >
< %systemroot%\system32\btz\*.* >
< %systemroot%\system32\EMP\*.* >
< %systemroot%\system32\expo\*.* >
< %systemroot%\system32\inet2\*.* >
< %systemroot%\system32\xrem\*.* >
< %ProgramFiles%\Microsoft\*.* >
< %systemroot%\usgwmt\*.* >
< %ProgramFiles%\B\*.* >
< %SYSTEMDRIVE%\lspp\*.* >
< %systemroot%\Kral\*.* >
< %SYSTEMDRIVE%\windowsdvd.exe\*.* >
< %systemroot%\system32\*.ipo >
< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >
< %systemroot%\system32\*.mof >
< %systemroot%\*.atm >
< %systemroot%\system32\svhost\*.* >
< %ProgramFiles%\system32\*.* >
< %ProgramFiles%\Docmentt\*.* >
< %systemroot%\Help\*.vbs >
< %ProgramFiles%\Windows WinSxs\*.* /s >
< %ProgramFiles%\Outlook Express\IDT\*.* /s >
< %ProgramFiles%\Microsoft Office\365\*.* /s >
< %ProgramFiles%\Windows Live\*.* >
< %systemroot%\system32\win32\*.* >
< %SYSTEMDRIVE%\RECYCLER\*.* >
< %systemroot%\Fresh1\*.* >
< %ProgramFiles%\Kekj\*.* /s >
< %systemroot%\GDU\*.* >
< %systemroot%\KA\*.* >
< %systemroot%\R\*.* >
< %systemroot%\system32\*.fyo >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-29 09:02:02
< End of report >